Added: 1 year ago
From: ChRiStIaAn008
Views: 12,885
Sort by time | Sort by thread (beta)

Link to this comment:

Share to:

All Comments (27)

Sign In or Sign Up now to post a comment!
  • this guy is fucking cool

  • This guy Joe is so awesome! i've leanred so much!

  • Hats off to Joseph, really enjoyed your presentation. Thanks

  • great guy for great tuto, good job

  • "Well now pentesting is different... You can't even walk in a barnes&noble without tripping over a security book"

    I found this funny, since there's an XSS vulnerability on barnes&noble's website. lol

  • @j0emccray Great presentation! I've been developing in PHP and MySQL for a few years and just recently had my first security issue. I used stumble upon to search for sql injection and stumbled onto this video. I probably could have taken a six week class and not gotten as much out of your presentation. Keep up the good work.

  • Great presentation!!!

  • This is one cool guy.

  • SQL Injection... AGAIN? at DEFCON in.....2011? Come on!

  • @viniciuskmax actually this talk was a few years ago. This is DC17, and we just had DC19 a few weeks ago.

  • When he starts he says I dont teach Basic sql injection - DUMFUCK THIS IS BASIC SQL INJECTION!

  • @Wolver1nEmkd - so what exactly would be more advanced? I covered Error, Union, Blind, exfil via DNS, dealing with errors, and IDS/WAF evasion. What would be better - stacked queries, magic quotes, UDF, what? PS..Dumbfuck??? really???? - I speak at conferences all over the world. I'd love to see you come to me and call me dumbfuck to my face.

  • @j0emccray You wouldn't want to get in trouble for beating up a twelve year old with a mental capacity of a sink plunger would you Wolve?

  • @j0emccray Something new maybe; i've had 4 lines of code in a common header file for years that owns every thing you have described. In your defence you really did nail it the coding needs to be stupidly flawed.

    The mention of param injection also makes no sense i mean i would seriously need to dynamicly run over _GET or _POST and just assume everything was valid and import them into my namespace.

    Meh learned nothing.

  • @j0emccray lmao, we all love you bro.

    And you're not here to clean ;D

  • @Wolver1nEmkd he taught you Advanced sick burn lol

  • Thumbs up for all his years of experience and everything he put into it

  • awesome :D

  • great watch

  • Also - incrementing the columns like that at 12:05 is long-winded.. It's better to use "ORDER BY column_number" - quicker and more efficient.

  • Just because it appears to be an integer doesn't always mean that it's actually an integer. You can have numerical strings.

  • ty for this lol :D

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more